First published: Mon Jul 02 2018(Updated: )
An issue was discovered in Zoho ManageEngine EventLog Analyzer 11.12. A Cross-Site Scripting vulnerability allows a remote attacker to inject arbitrary web script or HTML via the search functionality (the search box of the Dashboard).
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Zohocorp Manageengine Eventlog Analyzer | =11.12 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2018-10076.
The severity of CVE-2018-10076 is medium with a CVSS score of 6.1.
CVE-2018-10076 allows a remote attacker to inject arbitrary web script or HTML via the search functionality of Zoho ManageEngine EventLog Analyzer.
CVE-2018-10076 affects Zoho ManageEngine EventLog Analyzer version 11.12.
At the moment, there is no known fix for CVE-2018-10076. It is recommended to follow the vendor's security advisory for updates.